# Unassigned shards on cluster restart

**URL:** <https://discuss.elastic.co/t/unassigned-shards-on-cluster-restart/147146>\
**Category:** Elasticsearch\
**Created:** [September 4, 2018, 5:56am UTC](https://discuss.elastic.co/t/unassigned-shards-on-cluster-restart/147146 "2018-09-04T05:56:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![emanzaman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emanzaman/32/31960_2.png) [@emanzaman](https://discuss.elastic.co/u/emanzaman)\
**Post date:** [September 4, 2018, 5:56am UTC](https://discuss.elastic.co/t/unassigned-shards-on-cluster-restart/147146/1 "2018-09-04T05:56:41Z")

</div>

Hi, I am facing following issue:

1. Restarted my Elasticsearch cluster from one node to three nodes (two data nodes and one arbiter). But the cluster status is now red as shown below:

> $\> curl "nodeA:9200/\_cat/health"  
> 1536037434 06:03:54 graylog-uat red 3 2 13 12 0 0 1 0 - 92.9%

1. After some investigation, I landed upon the cluster allocation API and here is the output:

> $\> curl -X GET "nodeA:9200/\_cluster/allocation/explain?pretty=true"`  
> {  
> "index":"graylog\_0",  
> "shard":0,  
> "primary":true,  
> "current\_state":"unassigned",  
> "unassigned\_info":{  
> "reason":"CLUSTER\_RECOVERED",  
> "at":"2018-09-03T12:15:27.463Z",  
> "last\_allocation\_status":"no\_valid\_shard\_copy"  
> },  
> "can\_allocate":"no\_valid\_shard\_copy",  
> "allocate\_explanation":"cannot allocate because a previous copy of the primary shard existed but can no longer be found on the nodes in the cluster",  
> "node\_allocation\_decisions":[  
> {  
> "node\_id":"8W\_0X\_3UTY6twG7ZssfdTg",  
> "node\_name":"nodeB",  
> "transport\_address":"X.X.X.X:9301",  
> "node\_decision":"no",  
> "store":{  
> "found":false  
> }  
> },  
> {  
> "node\_id":"c\_K4VUSCQk-QV1mlquurhA",  
> "node\_name":"nodeA",  
> "transport\_address":"X.X.X.X:9301",  
> "node\_decision":"no",  
> "store":{  
> "found":false  
> }  
> }  
> ]  
> }

1. I can also see, in the log below, the index 'graylog\_0' getting deleted. If such is the case why is ES even searching for the said index.

> $\> zgrep "graylog\_0" \*  
> elasticsearch-2018-08-30.log.gz:2018-08-30 08:19:45,493 | INFO | o.e.c.r.a.AllocationService | Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[graylog\_0][0]] ...]). elasticsearch-2018-08-30.log.gz:2018-08-30 13:25:11,234 | INFO | o.e.c.m.MetaDataDeleteIndexService | [graylog\_0/HO0jj6QwTUmVaJn3OZQyZQ] deleting index

Elasticsearch version: 5.6.8

Could anyone point me to the right direction? Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2018, 5:58am UTC](https://discuss.elastic.co/t/unassigned-shards-on-cluster-restart/147146/2 "2018-10-02T05:58:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
